VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
References
| Link | Resource |
|---|---|
| http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 | Permissions Required |
| http://www.openwall.com/lists/oss-security/2025/09/29/10 | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00000.html | Mailing List Third Party Advisory |
| https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ | Exploit Third Party Advisory |
| https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-41244 | US Government Resource |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
|
History
06 Nov 2025, 13:58
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:a:vmware:tools:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:cloud_foundation_operations:9.0:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:vmware:open_vm_tools:13.0.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:open_vm_tools:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* |
|
| First Time |
Microsoft
Vmware tools Vmware Linux linux Kernel Debian Microsoft windows Linux Vmware cloud Foundation Operations Vmware aria Operations Vmware cloud Foundation Vmware telco Cloud Platform Debian debian Linux Vmware telco Cloud Infrastructure Vmware open Vm Tools |
|
| References |
|
|
| References | () http://support.broadcom.com/group/ecx/support-content-view/-/support-content/Security%20Advisories/VMSA-2025-0015--VMware-Aria-Operations-and-VMware-Tools-updates-address-multiple-vulnerabilities--CVE-2025-41244-CVE-2025-41245--CVE-2025-41246-/36149 - Permissions Required | |
| References | () https://blog.nviso.eu/2025/09/29/you-name-it-vmware-elevates-it-cve-2025-41244/ - Exploit, Third Party Advisory | |
| References | () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36149 - Vendor Advisory |
Information
Published : 2025-09-29 17:15
Updated : 2025-11-06 13:58
NVD link : CVE-2025-41244
Mitre link : CVE-2025-41244
CVE.ORG link : CVE-2025-41244
JSON object : View
Products Affected
vmware
- open_vm_tools
- aria_operations
- cloud_foundation_operations
- telco_cloud_platform
- telco_cloud_infrastructure
- tools
- cloud_foundation
debian
- debian_linux
microsoft
- windows
linux
- linux_kernel
CWE
CWE-267
Privilege Defined With Unsafe Actions
